---
title: "CVE-2013-2185\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-2185?format=md
keywords: index, follow
---

# CVE-2013-2185

Publication date 19 January 2014

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss
Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red
Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files
via a NULL byte in a file name in a serialized instance, a similar issue to
CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache
Tomcat team, although Red Hat considers it a vulnerability. The dispute
appears to regard whether it is the responsibility of applications to avoid
providing untrusted data to be deserialized, or whether this class should
inherently protect against this issue

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-2185?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat6 | 13.10 saucy | Ignored |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored |
| 12.04 LTS precise | Ignored |
| 10.04 LTS lucid | Ignored |
| tomcat7 | 13.10 saucy | Ignored |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored |
| 12.04 LTS precise | Ignored |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

upstream doesn't consider this to be a security issue, ignoring

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2185)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-2185)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-2185)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-2185)

### Other references

* <http://www.openwall.com/lists/oss-security/2013/09/05/4>
* <https://www.cve.org/CVERecord?id=CVE-2013-2185>
